Privacy Policy
Last updated: April 9, 2026
Trazo ("we," "us," or "our") provides an AI-powered art education platform designed for use in K-12 classrooms. We are committed to protecting the privacy of all users, especially children. This Privacy Policy explains how we collect, use, store, and protect information in compliance with the Children's Online Privacy Protection Act (COPPA), the Family Educational Rights and Privacy Act (FERPA), and applicable state privacy laws.
1. Information We Collect
1.1 Teacher Accounts (Adults)
When teachers register, we collect:
- Email address and display name (via Clerk authentication)
- Credit balance and usage history
- Uploaded images and generated artworks
- Classroom names and session history
1.2 Student Users (Children Under 13)
We do not collect any personally identifiable information (PII) from students. Specifically:
- No account creation required — students do not register, provide emails, or create passwords
- No names collected — students are identified only by a number or alias chosen by their teacher (e.g., "05" or "Student A")
- No device identifiers — we do not collect IP addresses, device IDs, or browser fingerprints from student sessions
- No tracking or analytics — we do not use cookies, pixels, or tracking technologies on student-facing pages
- No behavioral profiling — we do not build profiles of student behavior or preferences
1.3 Student-Created Content
Students upload drawings and receive AI-generated artwork. These images are stored temporarily and are associated with a classroom session, not with any personal identifier. Images are automatically deleted after the retention period described in Section 6.
1.4 AI Analysis Data
Trazo offers AI-powered analysis features that examine student artwork. These features generate educational feedback and do not involve any student-AI conversation or interaction. Analysis data includes:
- Art Element Recognition: Identifies use of the 7 elements of art (line, shape, color, value, form, texture, space) in a generated artwork
- Art History Connections: Suggests related famous artworks and art movements based on style characteristics
- Color Palette Extraction: Identifies dominant colors, color relationships, and color temperature
- Composition Analysis: Analyzes focal points, balance, and visual flow
- Class Trend Analysis (Teacher Only): Aggregated, anonymous analysis of class-wide artistic patterns — no individual student data is surfaced
- AI-Generated Lesson Plans (Teacher Only): Generates curriculum plans based on art style and grade level — no student data is used as input
- Student Progress Tracking (Teacher Only): Analyzes artistic growth across a student's portfolio over time
All AI analysis is one-way output only. Students cannot chat with, prompt, or interact with the AI in any way. The AI processes artwork and returns structured educational feedback. Teachers control when and how analysis is used.
AI Transparency: All AI-generated analysis includes a disclaimer that results are for educational reference only and do not replace professional teacher judgment. AI analysis may contain inaccuracies and should be used as a discussion starter, not an authoritative assessment.
2. How We Use Information
- To provide the AI art generation service
- To provide AI-powered educational analysis of artwork (art elements, color, composition, art history)
- To generate educational lesson plans and curriculum materials for teachers
- To provide teachers with aggregated class trends and individual student progress insights
- To manage classroom sessions and display student work to their teacher
- To manage teacher credits
- To maintain and improve the security of our platform
We do not use student data for advertising, marketing, AI model training, or any purpose unrelated to the educational service. Student artwork sent to Google Gemini for analysis is processed transiently and is not used to train AI models.
3. COPPA Compliance
Trazo is designed to comply with the Children's Online Privacy Protection Act (COPPA), including the updated rules effective April 22, 2026.
- School Consent Exception: When Trazo is used in a school setting, the school (through the teacher) provides consent on behalf of parents for the limited collection of student-created content, solely for educational purposes. This consent is governed by the school's relationship with parents under FERPA.
- No PII Collection: Since we do not collect names, email addresses, or any other personal identifiers from students, the scope of COPPA's requirements is significantly reduced.
- Parental Rights: Parents may contact us at any time to review, delete, or refuse further collection of their child's information by emailing privacy@trazo.art.
- Data Minimization: We collect only what is strictly necessary to provide the educational service.
4. FERPA Compliance
When used in schools, student artwork may constitute "education records" under FERPA. We comply with FERPA as follows:
- We act as a "school official" with a "legitimate educational interest" under the school's direction
- Student data is used solely for the educational purpose authorized by the school
- We do not share student data with any third parties except as necessary to provide the service (see Section 5)
- We do not sell, rent, or trade student information under any circumstances
- We are prepared to enter into Data Processing Agreements (DPAs) with school districts upon request
5. Third-Party Services
We use the following third-party services to operate Trazo:
Google AI (Gemini API)
Student drawings are sent to Google's Gemini API for AI processing. Google processes this data under their Data Processing Addendum. Google does not use API inputs to train their models. Images are processed transiently and not retained by Google after processing.
Supabase (Database & Storage)
Data is stored on Supabase infrastructure (AWS). All data is encrypted at rest and in transit. Supabase is SOC 2 Type II certified.
Clerk (Teacher Authentication Only)
Used only for teacher account authentication. Student sessions do not interact with Clerk in any way.
We do not use any advertising networks, analytics trackers, or social media plugins on student-facing pages.
6. Data Retention & Deletion
6.1 Student Data
- Student-uploaded images and generated artworks are retained while the classroom exists
- When a teacher deletes a classroom, all associated student data (uploads, artworks, session tokens, student numbers) is permanently deleted
- Teachers may download and export student work at any time
- Parents or schools may request immediate deletion by contacting us
6.2 AI Analysis Data
- Cached analysis results (art elements, palette, composition, art history) are stored alongside the artwork and are deleted when the artwork is deleted
- AI analysis data automatically expires after 90 days and is purged from our database. Teachers may re-run analysis at any time.
- Class trend analysis is generated on-demand and not stored — it is computed fresh each time a teacher requests it
- Progress tracking analysis is generated on-demand and not stored — it is computed fresh each time and not cached
- AI-generated lesson plans contain no student data and are displayed only in the teacher's browser session — they are not stored server-side
6.3 Teacher Data
- Teacher accounts and data are retained as long as the account is active
- Upon account deletion, all associated data (classrooms, works, uploads) is permanently removed within 30 days
6.4 Deletion Requests
Teachers, schools, or parents may request immediate deletion of any data by contacting privacy@trazo.art. We will process deletion requests within 5 business days.
7. Data Security
- All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Database access is restricted through Row-Level Security policies
- Student-facing pages require no authentication cookies or persistent identifiers
- API endpoints are rate-limited to prevent abuse
- Security headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy) are enforced
- Admin operations are logged with audit trails
8. Content Safety
All AI-generated content is filtered through safety rules designed for children:
- AI prompts explicitly prohibit violence, nudity, weapons, and inappropriate content
- Generated images are safe for all ages
- Teachers control which art styles are available to students
- Uploaded images are validated for file type and size
9. School District Agreements
We offer Data Processing Agreements (DPAs) for school districts. Our DPA template addresses:
- FERPA and COPPA compliance obligations
- Data ownership (the school retains ownership of all student-created content)
- Data breach notification procedures (within 72 hours)
- Data deletion upon contract termination
- Restrictions on data use (educational purposes only)
- Sub-processor disclosures
To request a DPA, contact schools@trazo.art.
10. Your Rights
Teachers, parents, and schools have the right to:
- Access all data we hold about them or their students
- Request correction of inaccurate data
- Request deletion of all data
- Export data in a portable format
- Withdraw consent at any time
- File a complaint with the FTC (for COPPA) or the Department of Education (for FERPA)
11. Virginia Student Data Privacy
Trazo complies with the Virginia Student Data Privacy Act (Code of Virginia § 22.1-289.01 et seq.). Specifically:
- We do not use student data for targeted advertising
- We do not sell student data under any circumstances
- We maintain a comprehensive data security program
- We delete student data upon request from the school division
- We provide transparency about what data is collected and how it is used
- We do not use student data to create commercial profiles
12. California Residents
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Age-Appropriate Design Code Act (CAADCA). We do not sell personal information. For California-specific requests, contact privacy@trazo.art.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to registered teachers via email and posted on this page. Continued use after changes constitutes acceptance. The "Last updated" date at the top of this page indicates when this policy was last revised.
14. Contact Us
For privacy-related questions, data requests, or DPA inquiries:
Email: privacy@trazo.art
School District Inquiries: schools@trazo.art